Dhamma Path
Privacy Policy
This policy explains how the Dhamma Path Android app (app.dhammapath) handles information.
Information we handle
Account and profile information
An account is required. You may authenticate using phone-number SMS OTP or Google Sign-In. Firebase Authentication processes the sign-in credential. We store a Firebase user ID (UID), name, phone number or email as applicable, optional profile image URL, language, selected teachers, sign-in method, onboarding state, notification preferences and tokens, platform, app version when available, account status, and created and last-active timestamps.
Features, support, and device data
- Alarm details may include schedule, repeat days, prayer selection, label, enabled state, and snooze duration. Alarm information and app preferences may be stored locally and, where the feature synchronizes it, in your account.
- Contact messages include your UID, subject, message, status, and handling timestamps. Do not include sensitive credentials.
- The app uses local caches and downloads to improve offline access and playback. Clearing app storage or uninstalling removes local app data, subject to Android behavior.
- Firebase Analytics receives engagement and diagnostic events such as feature interactions and sign-in attempt, success, or failure categories. It does not receive your password or OTP from Dhamma Path. Startup and repository errors are currently logged on-device; Firebase Crashlytics is not active.
- Photos you choose with the camera or gallery for status personalization remain on your device in the current implementation and are not uploaded by that feature. This is separate from an optional profile image URL or files stored under your user-owned cloud Storage path.
Why we use information
We use information to authenticate you; provide and secure your account; personalize language, teachers, content, and status features; deliver audio and other content; operate reminders, alarms, daily prayer, messaging, and notifications; answer support requests; prevent abuse; diagnose reliability issues; measure feature use; and improve the service.
Google and Firebase services
Dhamma Path uses Google Sign-In and Firebase services for Authentication, Cloud Firestore database and caching, Cloud Storage, Cloud Functions, Cloud Messaging, Analytics, Remote Config, and App Check abuse protection. These providers process data under their own terms and policies. App Check provider and enforcement behavior can vary by platform and environment; it supplements, but does not replace, authentication, authorization, and Firebase Security Rules. Firebase web configuration values and client code are not treated as secret security boundaries.
Android permissions and device access
- Notifications: show content and prayer notifications.
- Camera and media/storage: select or capture an on-device status photo, save downloads or wallpapers where Android requires access, and support older Android storage behavior.
- Wallpaper and system/ringtone settings: set a wallpaper or selected audio through Android integrations; changing protected system settings may require your explicit approval.
- Alarms, boot, wake lock, and notifications: schedule Daily Prarthana at the time you choose using Android Alarms & reminders, reschedule after restart, wake the device when needed, and play the prayer through a high-priority notification with Stop and Snooze. The app does not take over the lock screen and does not request a battery-optimization exemption; on some phones you can optionally set Battery to Unrestricted in Android app info if an alarm is delayed.
- Foreground media playback, internet, and network state: continue user-requested audio playback and retrieve online content reliably.
You can deny or revoke optional permissions in Android settings, but the related feature may not work.
Sharing and sale
We share information with the Google/Firebase processors described above only as needed to operate the app, and when required for security or law. Dhamma Path does not sell personal data, show advertising, or use unrelated marketing trackers in the current release.
Retention and deletion
Account and feature data is retained while your account is active and as needed to provide the service. Local caches remain until cleared by you or the operating system. Contact correspondence is retained as needed to resolve and document requests. You can request deletion through Profile → Delete Account or the public Delete Account page. Verified requests are reviewed and processed within 30 days.
Deletion normally removes the Firebase Authentication account, user profile, alarm records, notification tokens in the profile, and files under the user-owned Storage path. Minimal deletion proof, security and audit records, legally required records, aggregated or de-identified analytics, and support correspondence may be retained only as needed for those purposes and then limited or removed according to operational or legal requirements.
Security and your choices
We use Firebase Authentication, authorization checks, Security Rules, role-restricted administrative tools, transport encryption, and abuse-protection controls. No system is completely secure. You may manage notification and device permissions, clear local data, update profile choices, contact us about your data, or request account deletion. Never send passwords, OTP codes, private keys, service-account files, or payment credentials.
Policy updates
We may update this policy when the app or its data handling changes. We will revise the date above and provide notice in the app or through another appropriate channel when a change is material.
Contact
For privacy questions or requests, see Contact or email dhammapathai@gmail.com. Also review the Terms and Conditions.